FortiAuthenticator
FortiAuthenticator provides centralized authentication services for the Fortinet Security Fabric including multi-factor authentication, single sign-on services, certificate management, and guest management.
matanaskovic
Staff
Staff
Article Id 240234

Description

 

This article describes how to disable bypassing the FortiAuthenticator Agent login on a Windows machine.

 

Scope

 

FortiAuthenticator 6.4.6, FortiAuthenticator Agent 4.2.

 

Solution

 

Since it is possible to log in to a Windows machine without OTP and bypass the FortiAuthenticator Agent, it is recommended to disable 'Permit Built-in Password Providers' under the FortiAuthenticator Agent settings.

 

Navigate to Credential Provider Options -> Permit Built-in Password Providers.

Disable the setting and select Apply.

This setting must be configured manually on each PC.

 

matanaskovic_1-1671462255621.png

 

Lock the Windows machine and log in again, this time using the FortiAuthenticator Agent login window.

 

matanaskovic_1-1671466355980.png

 

Related documents:

Introduction live deployment

Introduction: FortiAuthenticator Agent for Microsoft Windows 4.2 Install Guide

FortiAuthenticator Agent for Microsoft Windows 4.2 release